dom-size
Pass
Audited by Gen Agent Trust Hub on Jul 31, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No prompt injection patterns, role-play overrides, or instructions to bypass safety guidelines were detected in the skill instructions or reference material.
- [DATA_EXFILTRATION]: No sensitive file access, hardcoded credentials, or unauthorized network operations were identified. The skill focuses on client-side performance metrics.
- [OBFUSCATION]: The content is provided in plain text and standard Markdown. No base64 encoding, zero-width characters, or homoglyph substitutions were found.
- [EXTERNAL_DOWNLOADS]: The skill references established documentation from trusted or well-known sources including frontendchecklist.io, web.dev, and developers.google.com. No automated remote code execution or suspicious downloads are present.
- [REMOTE_CODE_EXECUTION]: There are no patterns of piping remote scripts to shells or dynamic execution of untrusted code. Code examples provided are for illustrative purposes for React and HTML developers.
- [COMMAND_EXECUTION]: No dangerous system commands, privilege escalation (sudo), or persistence mechanisms (cron/bashrc) are included.
- [INDIRECT_PROMPT_INJECTION]: While the skill involves auditing code and performance data, it does not ingest untrusted data in a way that exposes the agent to execution risks. It follows best practices for manual and automated auditing.
Audit Metadata